web analytics

Microsoft Expands Copilot Bug Bounty Program, Increases Payouts – Source: www.securityweek.com

Rate this post

Source: www.securityweek.com – Author: Ionut Arghire

Microsoft on Friday announced an expansion to its Copilot bug bounty program to include more consumer products and provide researchers with higher incentives.

The same as before, bug hunters can earn up to $30,000 for critical-severity vulnerabilities in multiple Copilot AI products and services, but the payouts for medium-severity flaws have been increased.

“We are introducing new incentives for moderate severity Copilot cases. Researchers who identify and report moderate severity vulnerabilities will now be eligible for bounty rewards up to $5,000,” Microsoft announced.

Per the program’s rules, researchers can earn money by submitting reports of inference manipulation, model manipulation, inferential information disclosure, deserialization of untrusted data, code injection, authentication, SQL and command injection, server-side request forgery (SSRF), improper access control, and other types of security defects.

Now, they can also hunt for bugs in more Copilot consumer products, including Copilot for Telegram, Copilot for WhatsApp, copilot.microsoft.com and copilot.ai.

“This expansion provides researchers with more opportunities to contribute to the security of our Copilot ecosystem and helps us identify and mitigate potential vulnerabilities across a wider array of platforms,” Microsoft says.

The tech giant also notes that, building on the alignment with the AI bug bar, the Copilot bug bounty program has been integrated with its Online Services bug bar, to establish a consistent framework for evaluating the severity of flaws in Copilot consumer products.

“By aligning with the Online Services Bug Bar, we ensure that all reported vulnerabilities are assessed with the same rigor and standards applied across Microsoft’s online services. This not only streamlines the evaluation process but also enhances the transparency and fairness of our bounty rewards,” the company says.

Advertisement. Scroll to continue reading.

Microsoft is encouraging security researchers, developers, and enthusiasts to participate in the program. Additional information and the rules can be found on the Copilot bounty program’s page.

Related: Big Rewards Offered in Dedicated Google Cloud Bug Bounty Program

Related: Samsung Bug Bounty Program Payouts Reach $5M, Top Reward Increased to $1M

Related: Microsoft Bug Bounty Payouts Increased to $16.6 Million in Past Year

Related: Google Offering $250,000 for Full VM Escape in New KVM Bug Bounty Program

Original Post URL: https://www.securityweek.com/microsoft-expands-copilot-bug-bounty-program-increases-payouts/

Category & Tags: Artificial Intelligence,Vulnerabilities,AI,bug bounty program,Copilot,Microsoft – Artificial Intelligence,Vulnerabilities,AI,bug bounty program,Copilot,Microsoft

Views: 2

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post